Malware

Lazy.230549 (B) malicious file

Malware Removal

The Lazy.230549 (B) is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Lazy.230549 (B) virus can do?

  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Performs HTTP requests potentially not found in PCAP.
  • Unconventionial language used in binary resources: Chinese (Simplified)
  • The binary contains an unknown PE section name indicative of packing
  • The binary likely contains encrypted or compressed data.
  • The executable is compressed using UPX
  • Authenticode signature is invalid
  • Uses Windows utilities for basic functionality
  • Attempts to modify proxy settings
  • Harvests cookies for information gathering
  • Uses suspicious command line tools or Windows utilities

How to determine Lazy.230549 (B)?


File Info:

name: 25D499B18D8282D7CC5C.mlw
path: /opt/CAPEv2/storage/binaries/e646024441167df16bc4168059c6b527c9e07a4ddf63daac8054a3a2a75b46ef
crc32: 31AA7E03
md5: 25d499b18d8282d7cc5c98cc8a7caea7
sha1: b9fd167582a3209245c2cd60bd36d34d5486bda7
sha256: e646024441167df16bc4168059c6b527c9e07a4ddf63daac8054a3a2a75b46ef
sha512: e19a07e3a65c92d53608aeb606ebeb479b8d8bfdae74b2ffd678dd94b1fe9000f539f676c1be8edad488f8da089e987a504bcfa3a1e0aec52a7a1a30b98fbe4c
ssdeep: 12288:uyhveJM56XGvHq/xrJwUXD/vesjnOf3eMthkBtk:uEgXnreUT/veWOP3Itk
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T100F4F170A0A2887BD30A42735E572250F129FF911D5EC312A99FF7CF11BB6417A7A868
sha3_384: 84dd76192c47ea2f84e70ca08c17e6130cd72ab8b65d31146d0fe8b3e6281a5a0dfad2cc80e5ac4c295cbc30749b3145
ep_bytes: 60be00104f008dbe0000f1ffc787c8b4
timestamp: 2022-09-13 02:14:25

Version Info:

FileVersion: 1.0.0.1
LegalCopyright: Copyright (C) 2019
ProductVersion: 1.0.0.1
Translation: 0x0409 0x04b0

Lazy.230549 (B) also known as:

tehtrisGeneric.Malware
DrWebTrojan.Siggen17.50710
MicroWorld-eScanGen:Variant.Lazy.230549
FireEyeGeneric.mg.25d499b18d8282d7
ALYacGen:Variant.Lazy.230549
CylanceUnsafe
SangforTrojan.Win32.Save.a
K7AntiVirusSpyware ( 005690661 )
K7GWSpyware ( 005690661 )
CrowdStrikewin/malicious_confidence_60% (D)
BitDefenderThetaGen:NN.ZexaF.34646.TmKfauwTHrnj
SymantecML.Attribute.HighConfidence
Elasticmalicious (moderate confidence)
ESET-NOD32a variant of Win32/Spy.Agent.PYV
APEXMalicious
KasperskyHEUR:Trojan.Script.FBStealer.gen
BitDefenderGen:Variant.Lazy.230549
AvastWin32:PWSX-gen [Trj]
TencentWin32.AdWare.Extinstaller.Ssmw
Ad-AwareGen:Variant.Lazy.230549
EmsisoftGen:Variant.Lazy.230549 (B)
VIPREGen:Variant.Lazy.230549
Trapminesuspicious.low.ml.score
SophosTroj/Socelars-A
SentinelOneStatic AI – Malicious PE
JiangminTrojan.PSW.Disbuk.dj
GoogleDetected
AviraJS/SpyBanker.G2
MAXmalware (ai score=80)
MicrosoftTrojan:Win32/Sabsik.FL.B!ml
ZoneAlarmHEUR:Trojan.Script.FBStealer.gen
GDataGen:Variant.Lazy.230549
CynetMalicious (score: 100)
AhnLab-V3Trojan/Win.RedLineStealer.R511320
Acronissuspicious
VBA32BScope.Trojan.Agentb
MalwarebytesSpyware.Socelars.UPX
RisingSpyware.Agent!8.C6 (TFE:5:TppUMeSJi6V)
IkarusTrojan-Spy.Agent
FortinetW32/Socelars.S!tr.spy
AVGWin32:PWSX-gen [Trj]
Cybereasonmalicious.18d828

How to remove Lazy.230549 (B)?

Lazy.230549 (B) removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment